Skip to main content

secure-dependencies

星标16
分支2
更新时间2026年5月20日 12:50

Use this skill for any task involving dependency security: evaluating potential new dependencies before adding them, updating existing dependencies safely, or auditing the health and license status of current dependencies. Triggered by phrases like: - "update dependencies", "bundle update", "upgrade X" - "apply Dependabot alerts" - "add dependency X", "should I use X", "evaluate X", "is X safe to add" - "audit our dependencies", "are our deps healthy", "check our licenses", "review what we're using", "how maintained are our gems" - "securely update", "check for vulnerabilities in our dependencies" This skill guards against both unintentional vulnerabilities (insecure defaults, unmaintained projects, licensing problems that predict long-term security abandonment) and supply chain attacks (typosquatting, slopsquatting, package maintainer account takeovers, and malicious package developers)

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly